BSI ID: G 0.14
Espionage refers to attacks that aim to collect, evaluate and process information about companies, individuals, products or other targets. The processed information can then be used, for example, to give another company a competitive advantage, to blackmail individuals or to replicate a product. In addition to a variety of technically complex attacks, there are often much simpler methods of obtaining valuable information, for example by combining information from several publicly accessible sources that appear innocuous individually but can be compromising in other contexts. Since confidential data is often not adequately protected, it can often be spied on by optical, acoustic or electronic means.
Examples:
Many IT systems are protected against unauthorised use by identification and authentication mechanisms, e.g. in the form of user ID and password checks. However, if the password is sent unencrypted over the line, an attacker may be able to read it.
In order to withdraw money from an ATM, the correct PIN for the debit or credit card used must be entered. Unfortunately, the privacy screens on these devices are often inadequate, allowing an attacker to easily look over a customer's shoulder as they enter their PIN. If the attacker then steals the card, they can use it to empty the account.
To gain access rights to a PC or manipulate it in some other way, an attacker can send the user a Trojan horse, which they attach to an email as a supposedly useful program. In addition to immediate damage, Trojan horses can be used to spy on a wide range of information, not only about the individual computer, but also about the local network. Many Trojan horses are designed specifically to spy on passwords or other access data.
In many offices, workstations are not well soundproofed. This means that colleagues and visitors may be able to overhear conversations and gain access to information that is not intended for them or is even confidential.